Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-78159: The Events Calendar plugin lets attackers run code

CVE-2026-78159 · published 19 days ago
Summary

All versions of the The Events Calendar WordPress plugin up to 6.17.3 let anyone send specially crafted comments that cause the site to run their own code. This could let attackers take control of the server hosting your website. Update the plugin to the latest version or remove it if you cannot apply the update promptly.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
stellarwp the events calendar <= 6.17.3
Original advisory text
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation...
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). This makes it possible for unauthenticated attackers to execute code on the server. Exploitation requires that the targeted site has comments enabled on tribe_events posts and that at least one comment containing a crafted wp:legacy-widget block has been submitted, as the attack chain is triggered when do_blocks() processes the single-event HTML including the comment area.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
1% chance of attack within 30 days
Type
CWE-94Code Injection
Timeline
Published12 Sep 2026
Updated28 Sep 2026
First seen12 Sep 2026
Sources
CVE-2026-78159 · MITRE
Track software like this
Free during beta